Telecom News Hubb
Advertisement
  • Home
  • News
  • Telecom
  • Contact us
No Result
View All Result
  • Home
  • News
  • Telecom
  • Contact us
No Result
View All Result
Telecom News Hubb
No Result
View All Result
Home News

Microsoft called out for ‘blatantly negligent’ cybersecurity practices

admin by admin
August 4, 2023
in News


Microsoft is facing mounting criticism in the wake of last month’s attack on Azure. In a post on LinkedIn, Amit Yoran, the CEO of the cybersecurity company Tenable, says Microsoft’s cybersecurity track record is “even worse than you think” — and he has an example to back it up.

On July 12th, Microsoft disclosed a major breach targeting its Azure platform, which it traced to a Chinese hacking group known as Storm-0558. The attack affected around 25 different organizations and resulted in the theft of sensitive emails from US government officials. Last week, Senator Ron Wyden (D-OR) sent a letter to the US Department of Justice, asking it hold Microsoft accountable for “negligent cybersecurity practices.”

Yoran has more to add to the senator’s arguments, writing in his post that Microsoft has demonstrated a “repeated pattern of negligent cybersecurity practices,” enabling Chinese hackers to spy on the US government. He also revealed Tenable’s discovery of an additional cybersecurity flaw in Microsoft Azure and says the company took too long to address it.

Tenable initially discovered the flaw in March and found that it could give bad actors access to a company’s sensitive data, including a bank. Yoran claims Microsoft took “more than 90 days to implement a partial fix” after Tenable notified the company, adding that the fix only applies to “new applications loaded in the service.” According to Yoran, the bank and all the other organizations “that had launched the service prior to the fix” are still affected by the flaw — and are likely unaware of that risk.

Yoran says Microsoft plans to fix the issue by the end of September but calls the delayed response “grossly irresponsible, if not blatantly negligent.” He also points to data from Google’s Project Zero, which indicates that Microsoft products have made up 42.5 percent of all discovered zero-day vulnerabilities since 2014.

“What you hear from Microsoft is ‘just trust us,’ but what you get back is very little transparency and a culture of toxic obfuscation,” Yoran writes. “How can a CISO, board of directors or executive team believe that Microsoft will do the right thing given the fact patterns and current behaviors?”

Microsoft senior director Jeff Jones responded to Yoran’s criticism in an emailed statement to The Verge:

We appreciate the collaboration with the security community to responsibly disclose product issues. We follow an extensive process involving a thorough investigation, update development for all versions of affected products, and compatibility testing among other operating systems and applications. Ultimately, developing a security update is a delicate balance between timeliness and quality, while ensuring maximized customer protection with minimized customer disruption.



Source link

Previous Post

Huawei Cloud Pangu-Weather Model Now Available on European Weather Agency Website

Next Post

T-Rex Solutions Acquires Government IT Provider Cyber Cloud Technologies

Next Post

T-Rex Solutions Acquires Government IT Provider Cyber Cloud Technologies

Recommended

Target Worker Slams Customers Who Demand Item From App

June 5, 2023

Selling Cybersecurity: Five Ways to Get to Yes

February 21, 2023

Samsung’s new app uses AI to choose meals for you

September 3, 2023

Worker Says Employer Gave Him Worker’s Comp on Sticky Note

May 25, 2023

MSP M&A: DMI Acquires Mobility Management Company Simplex Mobility

January 25, 2023

Don't miss it

News

Huawei and China Mobile jointly released Green Management White Paper

October 1, 2023
Telecom

AI Companion Sends Summaries of Everything Said in Zoom

September 30, 2023
News

Charging Systems for Standalone 5G — A new paradigm for monetization

September 30, 2023
News

Tata Communications Limited to Acquire Kaleyra, Inc.

September 30, 2023
News

Why New York and other cities still aren’t prepared for floods

September 30, 2023
News

Notice on Rotating Chairman Tenure

September 30, 2023
Telecomm-white

© Telecomm News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Telecom
  • Contact us

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Telecom
  • Contact us

© 2022 Telecomm News Hubb All rights reserved.